CVE-2023-48648

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2023
Last modified:
29/08/2024

Description

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory with permissions greater than 0755 or when the permissions argument is not specified.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* 8.5.13 (excluding)
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* 9.0 (including) 9.2.2 (excluding)